Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <3408.1208430638@devserv.devel.redhat.com>
Date: Thu, 17 Apr 2008 07:10:38 -0400
From: Josh Bressers <bressers@...hat.com>
To: oss-security@...ts.openwall.com
Subject: Re: CVE request: firefox 2.0.14 ( Crash in JavaScript garbage collector)

> 
> And again, are pure browser crashers considered security relevant? I'd do so,
> as e.g. placing a crashing gif on e.g. some popular wiki could cause much
> trouble:
> http://www.securityfocus.com/bid/27243
> (I think it's still unfixed)
> 

As the advisory states:

    We have no demonstration that this particular crash is exploitable but
    are issuing this advisory because some crashes of this type have been
    shown to be exploitable in the past.

It is almost certain that given how Firefox is crashing, someone with the
time and know how could leverage this to execute arbitrary code.

-- 
    JB

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.